PT-2026-20988 · Calibre · Calibre

0X5T

·

Publicado

2026-02-20

·

Atualizado

2026-04-21

·

CVE-2026-26064

CVSS v4.0

9.3

Crítica

VetorAV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions calibre versions 9.2.1 and below
Description calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. A Path Traversal flaw exists in versions 9.2.1 and below, allowing arbitrary file writes where the user has write permissions. On Windows systems, this can lead to Remote Code Execution by writing a malicious payload to the Startup folder, which is then executed upon the next user login. The extract pictures function only verifies that file names start with 'Pictures' and does not properly sanitize '..' sequences. While calibre's ZipFile.extractall() function in utils/zipfile.py sanitizes '..' using get targetpath(), the extract pictures() function bypasses this protection by using manual zf.read() and open() operations.
Recommendations Update to calibre version 9.3.0 or later.

Exploit

Correção

RCE

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-04347
CVE-2026-26064
GHSA-72CH-3HQC-PGMP
OPENSUSE-SU-2026:10587-1

Produtos afetados

Calibre